Make changes based on the view (mostly name clarification).

This commit is contained in:
Mike Auty
2019-07-30 22:14:19 +01:00
committed by ikelos
parent f9e22d02de
commit f0a13c902e
4 changed files with 14 additions and 14 deletions
+3 -3
View File
@@ -37,7 +37,7 @@ from volatility.framework import constants, exceptions, interfaces, layers
from volatility.framework.configuration import requirements
from volatility.framework.layers import intel, scanners
from volatility.framework.symbols import intermed, native
from volatility.framework.symbols.windows import mspdb
from volatility.framework.symbols.windows import pdbconv
if __name__ == "__main__":
import sys
@@ -252,12 +252,12 @@ class KernelPDBScanner(interfaces.automagic.AutomagicInterface):
data_written = False
with lzma.open(potential_output_filename, "w") as of:
# Once we haven't thrown an error, do the computation
filename = mspdb.PdbRetreiver().retreive_pdb(
filename = pdbconv.PdbRetreiver().retreive_pdb(
guid + str(age), file_name = pdb_name, progress_callback = progress_callback)
if filename:
tmp_files.append(filename)
location = "file:" + request.pathname2url(tmp_files[-1])
json_output = mspdb.PdbReader(self.context, location, progress_callback).get_json()
json_output = pdbconv.PdbReader(self.context, location, progress_callback).get_json()
of.write(bytes(json.dumps(json_output, indent = 2, sort_keys = True), 'utf-8'))
# After we've successfully written it out, record the fact so we don't clear it out
data_written = True
+9 -9
View File
@@ -26,7 +26,7 @@ from volatility.framework.objects import utility
from volatility.framework.symbols import intermed
class PdbMSF(interfaces.layers.TranslationLayerInterface):
class PdbMultiStreamFormat(interfaces.layers.TranslationLayerInterface):
_headers = {
"MSF_HDR": "Microsoft C/C++ program database 2.00\r\n\x1a\x4a\x47",
"BIG_MSF_HDR": "Microsoft C/C++ MSF 7.00\r\n\x1a\x44\x53",
@@ -40,7 +40,7 @@ class PdbMSF(interfaces.layers.TranslationLayerInterface):
super().__init__(context, config_path, name, metadata)
self._base_layer = self.config["base_layer"]
self._pdb_symbol_table = intermed.IntermediateSymbolTable.create(context, self._config_path, 'windows', 'mspdb')
self._pdb_symbol_table = intermed.IntermediateSymbolTable.create(context, self._config_path, 'windows', 'pdb')
response = self._check_header()
if response is None:
raise ValueError("Could not find a suitable header")
@@ -171,13 +171,13 @@ class PdbMSFStream(interfaces.layers.TranslationLayerInterface):
self._pages_len = len(self._pages)
if not self._pages:
raise ValueError("Invalid/no pages specified")
if not isinstance(self._pdb_layer, PdbMSF):
raise TypeError("Base Layer must be a PdbMSF layer")
if not isinstance(self._pdb_layer, PdbMultiStreamFormat):
raise TypeError("Base Layer must be a PdbMultiStreamFormat layer")
@property
def pdb_symbol_table(self) -> Optional[str]:
layer = self._context.layers[self._base_layer]
if isinstance(layer, PdbMSF):
if isinstance(layer, PdbMultiStreamFormat):
return layer.pdb_symbol_table
else:
return None
@@ -222,10 +222,10 @@ class PdbMSFStream(interfaces.layers.TranslationLayerInterface):
return self.config.get('maximum_size', len(self._pages) * self._pdb_layer.page_size)
@property
def _pdb_layer(self) -> PdbMSF:
def _pdb_layer(self) -> PdbMultiStreamFormat:
if self._base_layer not in self._context.layers:
raise ValueError("No PdbMSF layer found: {}".format(self._base_layer))
raise ValueError("No PdbMultiStreamFormat layer found: {}".format(self._base_layer))
result = self._context.layers[self._base_layer]
if isinstance(result, PdbMSF):
if isinstance(result, PdbMultiStreamFormat):
return result
raise ValueError("Base layer is not PdbMSF")
raise ValueError("Base layer is not PdbMultiStreamFormat")
@@ -17,7 +17,6 @@
# WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License for the
# specific language governing rights and limitations under the License.
#
import argparse
import binascii
import datetime
import json
@@ -323,7 +322,7 @@ class PdbReader:
msf_layer_name = context.layers.free_layer_name("MSFLayer")
msf_config_path = interfaces.configuration.path_join("pdbreader", msf_layer_name)
new_context.config[interfaces.configuration.path_join(msf_config_path, "base_layer")] = physical_layer_name
msf_layer = msf.PdbMSF(new_context, msf_config_path, msf_layer_name)
msf_layer = msf.PdbMultiStreamFormat(new_context, msf_config_path, msf_layer_name)
new_context.add_layer(msf_layer)
msf_layer.read_streams()
@@ -922,6 +921,7 @@ class PdbRetreiver:
if __name__ == '__main__':
import argparse
class PrintedProgress(object):
"""A progress handler that prints the progress value and the description onto the command line"""